Rootkit

What is “Rootkit.Win32.Agent.einn”?

Malware Removal

The Rootkit.Win32.Agent.einn is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Rootkit.Win32.Agent.einn virus can do?

  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Rootkit.Win32.Agent.einn?


File Info:

name: F4A81BFD1EFFDDB27CFD.mlw
path: /opt/CAPEv2/storage/binaries/1f25fab9ee3ab94fb4af4fb20765ef5316da13ff5c32c1d4a5aec5328f16151f
crc32: DF742653
md5: f4a81bfd1effddb27cfdb8fb43b4dd0e
sha1: c766c7c9b4ec0c797621a193a0073eb3fa418644
sha256: 1f25fab9ee3ab94fb4af4fb20765ef5316da13ff5c32c1d4a5aec5328f16151f
sha512: 824d07e2bd1130566415815cbd1a3f4be440284932e498dbb648ae2ecb5dd3e5bb7b078e23774484b989ee8c7ff8e4f14d2fee067c629f2a1b6e3974a8d43d1e
ssdeep: 98304:tyOf70lG4JjrN3PgXXTW7BCsS0ILoEZIKnIO:tmxi0LS0AvIEIO
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D006D013F162C0F1F12C167911B72335AEB957942936CE97E3A0DE769D73290AB2720E
sha3_384: 21f6a08e973d244f11a4b7c54ebeae554e824e5c46fda9f75bf43a714141901cbc3edc47cb6f057397ccb794323813ae
ep_bytes: 558bec6aff68e8cf6c006834ce4f0064
timestamp: 2012-04-07 09:10:59

Version Info:

FileVersion: 1.0.0.0
FileDescription: why
ProductName: why
ProductVersion: 1.0.0.0
CompanyName: why
LegalCopyright: why
Comments: why
Translation: 0x0804 0x04b0

Rootkit.Win32.Agent.einn also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
DrWebTrojan.NtRootKit.14410
FireEyeGeneric.mg.f4a81bfd1effddb2
MalwarebytesGeneric.Malware.AI.DDS
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 005246d51 )
K7GWTrojan ( 005246d51 )
CrowdStrikewin/malicious_confidence_70% (D)
BitDefenderThetaGen:NN.ZexaF.36662.Nt0@aS!J2jnb
CyrenW32/OnlineGames.HH.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
APEXMalicious
ClamAVWin.Trojan.Blackhole-9963817-0
KasperskyRootkit.Win32.Agent.einn
AvastWin32:PUP-gen [PUP]
BaiduWin32.Trojan.FakeIME.d
McAfee-GW-EditionBehavesLike.Win32.Generic.wh
Trapminesuspicious.low.ml.score
SophosGeneric ML PUA (PUA)
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.1TYMTF4
GoogleDetected
Antiy-AVLTrojan/Win32.FlyStudio.a
XcitiumTrojWare.Win32.Agent.OSCF@5rs7jr
ZoneAlarmnot-a-virus:RiskTool.Win32.IMEStartup.ah
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Rootkitdrv.C5486546
VBA32BScope.Trojan.MulDrop
Cylanceunsafe
RisingStealer.QQPass!1.648F (CLASSIC)
IkarusTrojan.WinNT.Rootkitdrv
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/CoinMiner.PHP!tr
AVGWin32:PUP-gen [PUP]
Cybereasonmalicious.9b4ec0
DeepInstinctMALICIOUS

How to remove Rootkit.Win32.Agent.einn?

Rootkit.Win32.Agent.einn removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment